CVE-2019-10716
HIGHVerodin Director < 3.5.3.1 - Information Disclosure via /integrations.json API
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-10716. PoCs published by nxkennedy.
AI-analyzed exploit summary This exploit demonstrates an authenticated sensitive data disclosure vulnerability in Verodin Director Web Console versions prior to 3.5.4.0. It queries the REST API to retrieve credentials and configuration details of integrated security tools.
Description
An Information Disclosure issue in Verodin Director 3.5.3.1 and earlier reveals usernames and passwords of integrated security technologies via a /integrations.json JSON REST API request.
Exploits (1)
This exploit demonstrates an authenticated sensitive data disclosure vulnerability in Verodin Director Web Console versions prior to 3.5.4.0. It queries the REST API to retrieve credentials and configuration details of integrated security tools.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N